Courseiva
mediumDrag & Drop

CS0-003 Practice Question: Arrange the steps for a typical digital forensics…

Arrange the steps for a typical digital forensics investigation process.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Step 1: Identification, Step 2: Preservation, Step 3: Collection, Step 4: Examination, Step 5: Presentation

Digital forensics follows identification, preservation, collection, examination, and presentation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Step 1: Identification, Step 2: Preservation, Step 3: Collection, Step 4: Examination, Step 5: Presentation

    Why this is correct

    This sequence matches the standard forensic workflow codified in guidance such as NIST SP 800-86: analysts first identify which systems, media, or artifacts may hold relevant evidence, then preserve that evidence in its original state (isolating the device, disabling remote wipe, hashing volatile data) before physically or logically collecting it via forensic imaging, examining the acquired image for artifacts, and finally presenting findings in a report or testimony that a court or management can act on.

  • ✗

    Step 1: Preservation, Step 2: Identification, Step 3: Collection, Step 4: Examination, Step 5: Presentation

    Why it's wrong here

    Placing preservation before identification is backward because an investigator cannot take steps to protect evidence integrity, such as write-blocking a drive or isolating a host from the network, until they first determine which specific systems or artifacts are actually in scope; preservation actions applied blindly before identification risk missing evidence sources entirely or wasting resources protecting irrelevant systems.

  • ✗

    Step 1: Identification, Step 2: Collection, Step 3: Preservation, Step 4: Examination, Step 5: Presentation

    Why it's wrong here

    Swapping collection ahead of preservation breaks chain of custody because collection involves actively acquiring data from live or powered systems, and doing so before preservation controls are in place, such as write-blockers or volatile-memory capture order, risks overwriting timestamps, triggering anti-forensic wiping, or losing RAM contents that must be captured first under the order of volatility principle.

  • ✗

    Step 1: Identification, Step 2: Preservation, Step 3: Examination, Step 4: Collection, Step 5: Presentation

    Why it's wrong here

    Running examination before collection is logically impossible in this five-step model because examination refers to the detailed technical analysis of an already-acquired forensic image or artifact set, such as parsing file system metadata or carving deleted files; there is nothing to examine until a forensically sound copy of the evidence has first been collected from the preserved source.

About these practice questions

Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.